Test with GitLab CI/CD

  • Tier: Free, Premium, Ultimate
  • Offering: GitLab.com, GitLab Self-Managed, GitLab Dedicated

Use GitLab CI/CD to test changes in feature branches. You can display test reports and link to important information directly in merge requests.

Testing and quality reports

You can generate the following reports:

FeatureDescription
Accessibility testingDetect accessibility violations for changed pages.
Browser performance testingMeasure browser performance impact of code changes.
Code coverageView test coverage results, line-by-line coverage in diffs, and overall metrics.
Code qualityAnalyze source code quality with Code Climate.
Display arbitrary job artifactsLink to selected job artifacts using artifacts:expose_as.
Fail fast testingStop pipelines early when RSpec tests fail.
License scanningScan and manage dependency licenses.
Load performance testingMeasure server performance impact of code changes.
Metrics reportsTrack custom metrics like memory usage and performance.
Unit test reportsView test results and identify failures without checking job logs.

Baseline pipeline selection

Accessibility, Code Quality, license scanning, metrics, and unit test reports in merge requests compare source branch results with a baseline pipeline on the target branch. GitLab identifies the baseline pipeline using this process:

  1. Checks for a pipeline on the target branch that matches these commit SHAs, in order:
    1. The target branch tip at the time the merged results pipeline was created. This SHA is available only for merged results pipelines.
    2. The merge-base commit (the common ancestor of the source and target branches).
    3. The start commit of the merge request diff.
  2. Selects the most recently created pipeline (by pipeline ID) for the first SHA that has a matching pipeline.

The baseline pipeline selection:

  • Does not filter by pipeline status. A pipeline in any state, including running or failed, can be selected as the baseline.
  • Does not check whether the baseline pipeline has report artifacts.

The type of pipeline affects which commit SHA is matched first:

  • Merged results pipelines: The baseline is typically the latest pipeline at the target branch tip when the merged results pipeline was created.
  • Merge request pipelines and branch pipelines: The baseline is typically the latest pipeline on the target branch at the merge-base commit.

To ensure a baseline is always available for comparison:

  • Run pipelines on your target branch that produce the report artifacts you want to compare.
  • If you use merge request pipelines or branch pipelines, ensure the merge-base commit has a pipeline on the target branch.

Security reports

  • Tier: Ultimate

You can generate security reports by scanning your project for vulnerabilities:

FeatureDescription
Container scanningScan Docker images for vulnerabilities.
Dynamic application security testing (DAST)Scan running web applications for vulnerabilities.
Dependency scanningScan dependencies for vulnerabilities.
Static application security testing (SAST)Scan source code for vulnerabilities.